• V20: 3CX Re-engineered. Get V20 for increased security, better call management, a new admin console and Windows softphone. Learn More.

3cx System and a VPN tunnel for SIP traffic

Status
Not open for further replies.

Ben Beige

Joined
Aug 1, 2017
Messages
8
Reaction score
0
I've setup openVPN on an existing 3cx install to connect to an Asterisk instance that is providing a SIP trunk to replace an old PRI. this configuration works fine for outbound calls, but inbound calls run into issues w/ RTP not reaching the LAN IP on the interface.

09-Oct-2017 15:41:06.390 Leg L:62.2[Extn:230] is terminated: Cause: BYE from 172.18.253.121:3072
09-Oct-2017 15:41:01.807 Currently active calls - 1: [62]
09-Oct-2017 15:40:38.058 [MS105000] C:61.1: No RTP packets were received:remoteAddr=10.8.0.1:14074,extAddr=0.0.0.0:0,localAddr=172.18.253.10:10256
09-Oct-2017 15:40:36.610 Leg L:61.1[Line:10000<<4125555555] is terminated: Cause: BYE from PBX​

the VPN IPs are 10.8.0.1 (asterisk) / 10.8.0.6 (3cx)
(inbound number has been anonymized in the logs)

Can I make 3cx listen on both interfaces?
 
Route info from teh 3cx server:
===========================================================================
Interface List
19...00 ff 25 cc ba c1 ......TAP-Windows Adapter V9
11...00 9c 02 a0 45 a3 ......Broadcom NetXtreme Gigabit Ethernet
1...........................Software Loopback Interface 1
12...00 00 00 00 00 00 00 e0 Microsoft ISATAP Adapter
13...00 00 00 00 00 00 00 e0 Teredo Tunneling Pseudo-Interface
22...00 00 00 00 00 00 00 e0 Microsoft ISATAP Adapter #2
===========================================================================

IPv4 Route Table
===========================================================================
Active Routes:
Network Destination Netmask Gateway Interface Metric
0.0.0.0 0.0.0.0 172.18.253.1 172.18.253.10 266
10.8.0.1 255.255.255.255 10.8.0.5 10.8.0.6 20
10.8.0.4 255.255.255.252 On-link 10.8.0.6 276
10.8.0.6 255.255.255.255 On-link 10.8.0.6 276
10.8.0.7 255.255.255.255 On-link 10.8.0.6 276
127.0.0.0 255.0.0.0 On-link 127.0.0.1 306
127.0.0.1 255.255.255.255 On-link 127.0.0.1 306
127.255.255.255 255.255.255.255 On-link 127.0.0.1 306
172.18.253.0 255.255.255.0 On-link 172.18.253.10 266
172.18.253.10 255.255.255.255 On-link 172.18.253.10 266
172.18.253.255 255.255.255.255 On-link 172.18.253.10 266
224.0.0.0 240.0.0.0 On-link 127.0.0.1 306
224.0.0.0 240.0.0.0 On-link 172.18.253.10 266
224.0.0.0 240.0.0.0 On-link 10.8.0.6 276
255.255.255.255 255.255.255.255 On-link 127.0.0.1 306
255.255.255.255 255.255.255.255 On-link 172.18.253.10 266
255.255.255.255 255.255.255.255 On-link 10.8.0.6 276
===========================================================================
Persistent Routes:
Network Address Netmask Gateway Address Metric
0.0.0.0 0.0.0.0 172.18.253.1 Default
===========================================================================
 
first of all, VPN adapter should NOT be used and installed on 3CX hosts!

https://www.3cx.com/docs/manual/phone-system-installation-windows/

  • Do not install VPN software on your 3CX Server.
  • Ensure that all power saving options for your System and Network adapters are disabled (Set the system to High Performance).
  • Do not install TeamViewer VPN Option on the host machine.
  • Disable Bluetooth adapters if it is a client PC.
  • 3CX Phone System must not be installed on a host which is a DNS or DHCP server, has MS SharePoint or Exchange services installed.
Kindly change the setup to a routing gateway for VPN needs first before proceeding!
 
I may have over engineered my setup, and spent too much time in the asterisk world on this, as most of our asterisk PBXs are also openVPN servers. It turns out we have a tunnel to this site I am getting my network admins to just open ports for me.
 
Status
Not open for further replies.

Getting Started - Admin

Latest Posts

Forum statistics

Threads
141,635
Messages
748,994
Members
144,754
Latest member
deanhbs
Get 3CX - Absolutely Free!

Link up your team and customers Phone System Live Chat Video Conferencing

Hosted or Self-managed. Up to 10 users free forever. No credit card. Try risk free.

3CX
A 3CX Account with that email already exists. You will be redirected to the Customer Portal to sign in or reset your password if you've forgotten it.